Privacy notice
Operational draft · effective upon public launch
Information this site records
The executive systems audit records information you deliberately submit, including contact and organization details, role and decision authority, business priorities, affected functions, current workflows and systems, process and AI maturity, data and governance readiness, regulated-environment indicators, constraints, risks, timeline, investment range, desired outcomes, success measures, acceptance authority, consent, and technical request metadata used to operate and protect the service.
Purpose and operating use
Submitted information is used to evaluate fit, route the request, prepare a response, determine the smallest responsible engagement, preserve an auditable business record, prevent channel abuse, and establish a governed engagement only if both parties later agree in writing. Task-relevant in-house workflows may classify or summarize the record for the authorized Consulting Office; they do not create an engagement or final consulting conclusion without principal review.
Confidentiality and intellectual property
You retain ownership of your pre-existing information and intellectual property. Submission grants only the limited permission required to evaluate and respond to the request. Ghost Atlas does not sell submitted audit information or authorize its use to train a public or general-purpose model. Initial submission is not a substitute for a mutual confidentiality agreement where one is required.
Protected-data boundary
Do not submit passwords, tokens, payment-card data, regulated personal records, production datasets, classified or export-controlled material, source code, security vulnerabilities, or third-party intellectual property you are not authorized to disclose. Protected evidence enters only after an accepted engagement defines custody, access, clearance, retention, and disposal.
Access, service providers, and retention
Access is limited to the founder, authorized Estate functions, and task-relevant infrastructure or service providers operating under the applicable business configuration. Final legal entity, jurisdiction, retention schedule, subprocessor register, international-transfer terms, notice address, and deletion procedure must be completed with counsel before the custom-domain public launch.
Your request
After public launch, the published business contact channel will accept applicable access, correction, restriction, or deletion requests. Identity and authority may be verified before a request is executed, and some records may be retained when required for security, contractual, evidentiary, or legal purposes.